CVE-2026-41636
published 2026-04-28CVE-2026-41636: Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
37.6th percentile
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | < 0.23.0 | 0.23.0 |
| apache | thrift | >= 0 < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_thrift | < 0.23.0 | 0.23.0 |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| openshift-service-mesh | istio-rhel8-operator | — | — |
| openshift4 | oc-mirror-plugin-rhel9 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhosdt | opentelemetry-collector-rhel9 | — | — |
| rhosdt | tempo-jaeger-query-rhel9 | — | — |
| rhosdt | tempo-query-rhel9 | — | — |
| rhosdt | tempo-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion
vendor_redhat·2026-04-28·CVSS 8.7
CVE-2026-41636 [HIGH] CWE-776 apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion
apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion
No description is available for this CVE.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Affected
Package: openshift-service-mesh/istio-rhel8-operator (OpenShift Service Mesh 2) - Affected
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-cuda-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-rocm-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhaiis/vllm-tpu-rhel9 (Red Hat AI Inference Server) - Affected
Package: rhelai3/bootc-aws-cuda-rhel9 (Red Hat Enterprise Linux AI (RHEL AI) 3) - Affected
Pack
VulDB
Apache Thrift up to 0.22.0 Node.js skip recursion
vuldb·2026-04-28·CVSS 8.7
CVE-2026-41636 [HIGH] Apache Thrift up to 0.22.0 Node.js skip recursion
A vulnerability, which was classified as problematic, has been found in Apache Thrift up to 0.22.0. This issue affects the function skip of the file Node.js. Performing a manipulation results in uncontrolled recursion.
This vulnerability was named CVE-2026-41636. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion
ghsa·2026-04-28
CVE-2026-41636 [HIGH] CWE-674 Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion
Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41636 golang-github-apache-thrift: Apache Thrift: Node.js skip() recursion [fedora-all]
bugzilla·2026-04-30·CVSS 8.7
CVE-2026-41636 [HIGH] CVE-2026-41636 golang-github-apache-thrift: Apache Thrift: Node.js skip() recursion [fedora-all]
CVE-2026-41636 golang-github-apache-thrift: Apache Thrift: Node.js skip() recursion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41636 apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion
bugzilla·2026-04-28·CVSS 8.7
CVE-2026-41636 [HIGH] CVE-2026-41636 apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion
CVE-2026-41636 apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
2026-04-28
Published